Jump to content

WARNING: "MilkCat Animations" mod contained malware (info-stealer)


Recommended Posts

Posted

⚠️ WARNING: "MilkCat Animations" mod contained malware (info-stealer) check your PC if you downloaded it

I'm posting this to warn the community. A few days ago my PC was infected by an info-stealer (a malware family that steals saved browser passwords, cookies/sessions, and Discord tokens). After a full investigation, the infection was traced to a Sims 4 script mod called "MilkCat Animations", which I had downloaded from here.

What I observed:

The malware landed on disk within ~2 seconds of the game finishing loading its mods.
Unlike every other script mod I had installed, MilkCat's .ts4script contained obfuscated code and an encrypted payload disguised as a normal Python file — a clear sign it wasn't a real animation mod.
The file and the uploader's account have since been removed from the site, which fits the pattern of a malicious upload via a hacked or fake account.
If you downloaded "MilkCat Animations", please do the following:

Delete the mod immediately (all .ts4script files associated with it).
Change the passwords of any account whose password was saved in Chrome/Edge especially email, and anything with payment info. Prioritize reused passwords.
Log out of all sessions on your important accounts (a stolen cookie survives a password change until you do).
Reset your Discord password and enable 2FA Discord tokens are a primary target.
Run a scan with a reputable tool (e.g. Malwarebytes) as a second opinion.
Enable 2FA everywhere you can  it makes a stolen password useless.
Stay safe, and please only install script mods from trusted, well-known creators. When in doubt, a .ts4script is just a ZIP you can inspect it before installing.

  • 2 weeks later...
Posted (edited)

Word for Wisdom:  Animation and clothing packages should never need a .script file to function, always be very suspicious of uploaded content that has a .script, script files are python code and python can do anything it wants to your system or bring in some new payload that does the really bad stuff like what happened to you.

 

I have been spotting uploads from old accounts with a similar tactic of some AI created software description that is Sims oriented, always some 'stand-alone windows application' and I'm confirming they always have malicious code embedded in them by running them through Virus Total, MS Defender has not been catching them, a few of them are even showing up under different names but Virus Total sees they are the same malicious payloads so its the same people abusing compromised accounts lists around the internet that let them access this site.

 

I've also seen 'animation packs' like the one that got you that are repackaged content from creators just renamed and with a malicious python .script file,  the one that got you was re-tried as a different name a few days ago but Virus Total saw it was the same malicious python script payload.

 

I don't know if other sub forums are being attacked the same way but its a campaign and I think the site moderates could protect this community by cleaning house and disabling really old accounts that haven't visited the site, its almost always accounts that were created around 2016 and have never posted before the day they uploaded the malware as bait for people to download.  There are websites with lists of compromised LovesLab site accounts and their passwords all over the place, I found a bunch when I went looking.

Edited by veegee96

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...